Improper Authentication in team-alembic AshAuthentication
CVE-2026-80218
What is CVE-2026-80218?
The AshAuthentication framework in team-alembic is vulnerable to improper authentication, allowing attackers with access to a sign-in token for one authenticated resource to potentially gain unauthorized access to a user account in a different resource. This flaw arises from the way in which the JWT token's subject claim is parsed, specifically when the URI's path segment is disregarded. As a result, the system wrongly associates the sign-in token with various resources which share identical primary-key field names. It is important for developers to be aware of this vulnerability and implement necessary patches to safeguard user authentication.
Affected Version(s)
ash_authentication 3.10.5 < 4.15.0
ash_authentication 5.0.0-rc.0 < 5.0.0-rc.14
ash_authentication eca8cadea0f1595ed2c10a0c177b1da9aa9e5269
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
